Root has patched CVE-2026-56409 in the expat package for Root:Debian:12. Multiple fixed versions available.
{
"distro": "debian",
"distro_version": "12",
"severity": "MEDIUM",
"source": "Root"
}[
"2.5.0-1+deb12u2.aikido.18",
"2.5.0-1+deb12u2.aikido.19",
"2.5.0-1+deb12u2.aikido.20"
]
"aikido.20"
true
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-12-CVE-2026-56409.json"
3
"2.5.0-1+deb12u2"
[
"2.5.0-1+deb12u2.aikido.18",
"2.5.0-1+deb12u2.aikido.19",
"2.5.0-1+deb12u2.aikido.20"
]
"aikido.20"
true
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-12-CVE-2026-56409.json"
3
"2.5.0-1+deb12u2"